Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Drift Boss Original

acfjniffcmahollkfpmbafogeknigieg
Risk Score
5.41
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 418
Rating
Last updated 2024-01-27 (31 months ago)
Manifest version MV3
CSP present ✅ yes
Developer johnkarik2023@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy URL unreachable (fetch_error) — effectively no privacy policy disclosed.
  • 31 months without update — zombie extension with active installs.
  • Uninstall URL hijack + install URL hijack redirecting to drift-boss.me on install.
  • Free-webmail dev (gmail), no developer name, no verified publisher — identity unverifiable.
  • Sandbox CSP uses unsafe-eval and unsafe-inline enabling script execution in sandboxed pages.

Evidence

  • uninstall_url_hijack + install_url_hijack crx onInstalled opens https://drift-boss.me/#welcome; uninstall URL also hijacked — Webstore +3.0+2.0.
  • privacy_policy_fetch_error crx games777.io/privacy-policy/ returned ConnectionError — treated as fetched==false → Privacy +10.0.
  • free_webmail_no_dev_name store Developer johnkarik2023@gmail.com, no developer_name — Reputation floor 7.5 (free-webmail + no name).
  • months_since_update_31 store 31 months since last update → Maintenance +8.5 (24-36mo band).
  • sandbox_unsafe_eval crx Sandbox CSP includes unsafe-eval and unsafe-inline on script-src — elevated code execution risk.
  • dom_sink_innerhtml_userctrl crx rate.js uses innerHTML from variable — DOM-XSS sink; csp_present==true limits severity → +0.5.
  • js_external_hosts crx Contacts zenadservices.net (ad-tech), statics.games-storage-aws.yandex.net (RU CDN), github.com, drift-boss.me.
  • triple_stale_fingerprint store 31mo stale + MV3 + no CVEs — v2 calibration triple-stale only requires >24mo+CVEs+MV2; partial match, no bonus.

Pillar Scores

Permissions0.00
Reputation7.50
Network2.00
Webstore6.00
Maintenance8.50
Privacy10.00
Code Quality2.00
CVE Exposure0.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-31 05:14
Listing SHA 46ccf3a8564c…
Force block — not fired
Score recovered no
Elapsed